Re: Access Rule for OutLook mail from Exernal ISP

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



I tried your suggestion by starting a query it indicated the following
information:

Client IP =123.56.78.910
Destination IP = 21.217.9.25
Destination Port = 53
Protocol = DNS
Action = Denied Connection
Rule = [Enterprise] Default rule
Result Code = 0xc004000dFWX_E_POLICY_RULES_DENIED

It does appear the my e-mail is being blocked by the information above. But
I don't understand why? From my reading the Default Enterprise rule can not
be changed. So how do I reslove this issues? Why is DNS an issue here.
I've created other rules regarding surfing the internet for a restricted set
of users and did not have any problems.

Can you tell me what must be done to get my e-mail working? I would also
like for you to point me in a direction where I can better understand the
solution to my problem.

Thanks




"Phillip Windell" wrote:

> "Larry Bird" <LarryBird@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:9C9CEE0F-8B89-4589-8D8D-B3CF1C583C57@xxxxxxxxxxxxxxxx
> > To try and make things work, I created to user defined protocols for SMTP
> and
> > POP3. Creating these User-Defined protocols then allowed me to define the
> > direction and port. For SMTP I used 25 for POP3 I used 110. Neither made
> > any difference.
>
> Correct. You use the ones that are there,..you don't create anything for
> something this simple when they already exist anyway. The "directions" are
> already correct on the ones that already exist. Make sure you use the ones
> labled "SMTP" and "POP3",...do *not* use "SMTP Server" or "POP3 Server".
> If the connection is SSL based you can also add "SMTPS" and "POP3S",..but I
> would be really really surprised if that what is being done.
>
> Two things I can think of:
>
> 1. Go to the Networks Object in the ISA MMC. Select the Internal Network
> Definition. Right-click on it and pick properties,...Select the Firewall
> Client Tab. Make sure it is enabled and the ISA Server name shows. In the
> one in my test lab I have everything checked and the Radio Button is set to
> "Use Default URL"
>
> 2. Go to the Monitoring Object in the ISA MMC. Select the Logging Tab.
> Select "Start Query". While that is running, try one of the SMTP/POP3
> Clients. The Log Monitor will tell you if something is being denied. It
> will tell you which Rule is doing the deny and which Protocol is being
> attempted and will show both the Client and Destination IP#.
>
> --
> Phillip Windell [MCP, MVP, CCNA]
> www.wandtv.com
> -----------------------------------------------------
> Understanding the ISA 2004 Access Rule Processing
> http://www.isaserver.org/articles/ISA2004_AccessRules.html
>
> Microsoft Internet Security & Acceleration Server: Guidance
> http://www.microsoft.com/isaserver/techinfo/Guidance/2004.asp
> http://www.microsoft.com/isaserver/techinfo/Guidance/2000.asp
>
> Microsoft Internet Security & Acceleration Server: Partners
> http://www.microsoft.com/isaserver/partners/default.asp
>
> Deployment Guidelines for ISA Server 2004 Enterprise Edition
> http://www.microsoft.com/technet/prodtechnol/isa/2004/deploy/dgisaserver.mspx
> -----------------------------------------------------
>
>
>
>
>
>
.



Relevant Pages

  • Re: Windows 2008 TSG THRU ISA 2006
    ... Jim Harrison (ISA SE) ... Original Client IP Client Agent Authenticated Client Service Referring ... Server Destination Host Name Transport HTTP Method MIME Type Object ... SourceSourceProxy Destination Proxy Bidirectional Client Host Name Filter ...
    (microsoft.public.isa.publishing)
  • Re: Serious(ly weird) ISA 2004 problem
    ... Log Time Destination IP Destination Port Protocol Action Rule Client IP ... Information Original Client IP Server Name Referring Server Destination ... > ISA rule which routes them all internally to the same web server and same ...
    (microsoft.public.isa)
  • Re: ISA blocking outbound - strange
    ... outbound connections over protocol needed? ... when this app is done on a PC on the LAN with the ISA ... > FW client enabled, I observe that there is some traffic ... > LDAP server directly, but it first has to pass thru ISA. ...
    (microsoft.public.isa)
  • Re: isa server
    ... > I understand that after you installed ISA server, ... > access the Internet and the MSN Messenger does not support the NTLM ... Create a Protocol Rule to allow HTTP and HTTPS protocols. ... > solution is to install the firewall client on the client machines. ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange 2007 TSG Thru ISA 2006
    ... Jim Harrison (ISA SE) ... The following "denied" is logged on the ISA server: ... Original Client IP Client Agent Authenticated Client Service Referring ... SourceSourceProxy Destination Proxy Bidirectional Client Host Name Filter ...
    (microsoft.public.isaserver)